Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Link
Accept-Ranges
CF-RAY
ETag
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Content-Encoding
Access-Control-Expose-Headers
P3p
X-Drupal-Dynamic-Cache
X-CDN
X-AspNetMvc-Version
Upgrade
X-Via
CF-Ray
X-Ws-Request-Id
Access-Control-Max-Age
X-Request-ID
Server-Timing
EagleId
X-Cache-Group
Keep-Alive
X-Turbo-Charged-By
Request-Context
X-Ua-Compatible
X-Age
X-Server-Powered-By
X-Proxy-Cache
X-UA-Device
X-AH-Environment
X-Backend
X-Hacker
X-Robots-Tag
Report-To
X-Amz-Request-Id
Host-Header
X-Server
X-Amz-Id-2
Grace
X-LiteSpeed-Cache
X-Rq
X-Nginx-Cache-Status
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Page-Speed
X-Vhost
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Pingback
X-Dispatcher
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Host
X-Server-Id
Cf-Railgun
X-Node
X-Backend-Server
X-Readtime
Accept-CH
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-Response-Time
X-HW
Xkey
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Application-Context
Content-Location
Rating
X-Country
X-B3-TraceId
X-Cache-Lookup
X-Cloud-Trace-Context
X-Trace
X-Url
X-Ac
X-Content-Type
Accept-CH-Lifetime
X-Vname
X-PC
X-TtlSet
Allow
X-Varnish-TTL
X-Clacks-Overhead
X-Mod-Pagespeed
Edge-Control
X-ESI
X-Server-Name
Fastly-Restarts
Cache-Tag
X-FastCGI-Cache
Service-Worker-Allowed
X-VARITI-CCR
X-Rack-Cache
Verso
X-Element-Page-Cache
X-MS-InvokeApp
X-GitHub-Request-Id
X-Upstream
MS-Author-Via
Accept-Ch
X-Amz-Rid
X-Aws-Lambda-Call-Status
Public-Key-Pins
X-Vcap-Request-Id
X-Cached
X-Dw-Request-Base-Id
X-Client-IP
X-D2id
X-Abt-Application-Version
X-Cnection
X-Origin-Cache
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Px
X-Country-Code
Access-Control-Request-Method
X-Navigation-Version
RTSS
X-Goog-Hash
X-Powered-By-Plesk
X-NF-Request-ID
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Exp-Variant
X-Exp-Id
X-Use-Magma
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja
X-Powered-CMS
X-Version
X-Language
AR-SID
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-Request-ID
X-Sol
Display
Pagespeed
X-Middleton-Display
X-Amz-Server-Side-Encryption
X-Middleton-Response
Response
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-MSEdge-Ref
X-LLID
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
X-RateLimit-Remaining
Nginx-Cache
X-Template
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Protected-By
X-Shield-Request-Id
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-TTL
TCN
X-T
X-Forwarded-For
S
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Mg-S
X-Id
Content-MD5
Edge-Cache-Tag
X-Mid
Realpath
Fastcgi-Cache
SPIisLatency
SPRequestDuration
Front-End-Https
X-MCACHE
X-Ttl
X-CST
X-Recruiting
X-Request-Received
X-Request-Processing-Time
Filters
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Server-Node
X-DynaTrace
X-Ab
X-Content
X-Ua-Browser
Server-Name
X-Frontend
X-Correlation-Id
X-ECACHE
X-NWS-LOG-UUID
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
SPRequestGuid
X-SharePointHealthScore
Fusion-Template-Id
X-HS-Combine-CSS
X-Parallel-Accel
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Source
Fusion-Deployment-Id
X-Ezoic-Cdn
X-Yandex-Sdch-Disable
X-Cache-Key
X-Hits
Alternate-Protocol
X-Ser
X-Content-Options
X-Buckets
X-Tt-Trace-Host
X-Tt-Trace-Tag
MicrosoftSharePointTeamServices
X-Page-Id
Cache-Tags
X-Ruxit-Js-Agent
X-Git-Hash
X-B3-Sampled
Charset
Host
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Cleartype
X-Www-Served-By
X-Geo-Country
X-DIS-Request-ID
X-Daa-Tunnel
X-Accel-Expires
X-Amzn-Trace-Id
X-Content-Digest
X-Amz-Replication-Status
X-Debug-Info
Filterid
X-Varnish-Age
X-Fastly-Request-Id
X-AppVersion
X-Hostname
X-Activity-Id
X-Az
X-Forwarded-Proto
X-FB-Debug
TP-Cache
TP-L2-Cache
X-Upgrade-Enabled
X-VCache
X-N
X-Rid
Access-Control-Allow-Method
X-Origin-Server
X-Grace
Cross-Origin-Opener-Policy
X-Nginx-Upstream-Cache-Status
X-LB-Cache
X-F-Cache
X-Mobile-URL
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Request-Guid
X-Route-Name
X-Flags
X-Providence-Cookie
ServerID
X-Server-ID
X-Whom
X-XRDS-LOCATION
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-TT
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-App-Environment
X-Varnish-Grace
X-Tb
Node
Payment
Viewport
X-Seen-By
X-FW-Serve
X-WebKit-CSP-Report-Only
X-FW-Hash
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Dynamic
X-App-Server
X-Type
X-Distributor
DC
Paypal-Debug-Id
X-Origin-Upstream-Status
X-NGENIX-Cache
X-Ratelimit-Limit
X-User-Agent
Fastcgi-Useragent
X-Cache-Control
Country
Accept-Charset
X-Litespeed-Cache
X-Fastcgi-Cache
X-Wix-Request-Id
X-Logged-In
X-Cache-Rule
X-Request-Handler-Origin-Region
X-Microsite
X-Fastly-Request-ID
X-Webkit-CSP
Version
X-DataDome
X-Cache-Age
X-Via-JSL
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Drupal-Cache-Tags
X-Erf-Bev-Bev
Referer-Policy
X-Browser-Type
Amp-Access-Control-Allow-Source-Origin
X-Erf-Bev-Bev-Is-Generated
X-Varnish-Backend
Refresh
X-Cluster-Name
Cache-Status
X-Load-Cache
X-Node-Name
X-Contextid
X-Signature
X-B-Cache
X-Response-Served-From
X-Original-Request-Id
Access-Control-Request-Headers
X-Mobile
SD-X-WS
X-Real-IP
X-Rendered-As
X-Vgn-Hpd-Reason
X-Proxy-Cache-Status
X-Jobs
X-Cacheable-TTL
X-Cache-Action
X-Cache-Expired-At
X-Is-Bot
X-Page-View
X-ProcessESI
X-Revision
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Debug
X-B
X-RemovedCookies
X-UUID
NGB
X-IPLB-Instance
X-Rule
X-Yottaa-Metrics
X-Proxy
X-Device-Type
X-Yottaa-Optimizations
X-Instance
Surrogate-Key
X-Cache-Time
Akamai-GRN
X-Framework
X-Drupal-Cache-Contexts
X-Tec-Api-Origin
X-G
X-Tec-Api-Version
X-Tec-Api-Root
X-Debug-IsConnected
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Debug-IsPreview
X-TEC-API-VERSION
CF-IPCountry
X-FW-Version
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
SID
X-PressLabs-Stats
DynaTrace
Liferay-Portal
X-Azure-Ref
X-Oneagent-Js-Injection
Healthy
X-Nginx-Cache
GEO-INFO
Frame-Options
X-CDN-Forward
X-Ratelimit-Reset
X-Ms-Request-Id
X-Ms-Version
X-Source
Count-Hit
X-Presslabs-Stats
X-Cache-Operation
MS-CV
X-Accel-Buffering
X-RTag
Ms-Operation-Id
X-XRDS-Location
Uber-Trace-Id
X-EdgeConnect-Cache-Status
X-RateLimit-Limit
X-APP-VERSION
X-Tumblr-User
Xserver
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-L-Path
X-Environment-Context
X-Tumblr-Pixel
Countrycode
X-Cache-Hit
X-Varnish-Server
X-Zen-Fury
Ec-Rule-Version
X-Mode
X-Backend-Name
Cross-Origin-Window-Policy
X-Forwarded-Host
X-Cache-NGX
X-Region
Backend
X-Servername
X-IPS-LoggedIn
X-Content-Powered-By
X-RN-RSRV
X-UPSTREAM-Address
Protected
Meta-Geo
X-SaId
X-Cache-Type
X-Rewrite-Enabled
X-Cache-TTL-Remaining
X-JoinUs
X-Detected-As
X-Extlb
X-Generation-Time
X-Shopify-Stage
X-Varnish-Beresp-Grace
X-Routing-Service
Decoy-Debug-Key
X-ShardId
Section-Io-Cache
X-Alternate-Cache-Key
Eomportal-Instance
Decoy-Debug-TTL
Decoy-Debug-Status
Country-Code
Fastly-SSL
Apigw-Requestid
X-Cache-Server
X-Sql-Count
X-Tid
X-Cache-Grace
X-Debug-Cache
X-ShopId
X-NewRelic-App-Data
X-Human
X-Redis-Cache
X-Uri
X-Zipkin-Id
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Sql-Duration-Ms
X-Proxied
X-Hosted-By
X-PERF
X-Microcachable
X-BYPASS-REASON
X-ApacheServer
Url
X-PHP-Backend
X-Soup
X-UA-Device-Type
X-No-Session
Mn-Server-Ip
X-ProxyCache-Key
X-Status
X-Storage
X-NYM-Debug-Backend
X-NCache
X-Origin-Date
X-Via-Fastly
X-ServerID
X-Format
Cache-Name
X-FB-TRIP-ID
Cache-Tv-Group
X-Site-Version
X-ProxyCache-Status
TWC-GeoIP-Country
TWC-Device-Class
X-Say-TTL
X-Server-W
Property-Id
Selected-Fe
TWC-Connection-Speed
X-Adobe-Loc
X-SayCDN-TTL
X-Akamai-Edgescape
X-PCL
X-Origin-Hint
X-Say-Cacheable
X-Section
X-OCL
X-Cluster-Node
X-Web-Node
X-Adobe-Content
TWC-Privacy
TWC-Locale-Group
X-Proxy-Build
Webcakes-App-Name
Webcakes-App-Version
X-Timing-Wait
Webcakes-Region
TWC-GeoIP-LatLong
X-Access
X-Content-Age
SRV
DB-Nickname
X-Hl-Ver
OT-Force-Account-Verify
X-Varnishpool
X-Cache-Host
X-Pubstack
Azure-InstanceId
X-R9-Blue-Green-Version
Azure-SlotName
Azure-RegionName
Azure-Version
Azure-SiteName
X-Hyper-Cache
X-Be
Content-Secure-Policy
X-LSADC-Cache
CDN-CachedAt
CDN-RequestCountryCode
CDN-RequestId
CDN-PullZone
CDN-EdgeStorageId
CDN-Cache
X-Webkit-Csp
CDN-Uid
X-Azure-Ref-OriginShield
LB
X-Generated-By
X-Ua
Content-Disposition
WPO-Cache-Message
X-Cached-By
Source
WPO-Cache-Status
Cache
X-TIME
X-Nginx-Cache-Key
X-App-Version
X-Unique-Id
X-LAGOON
X-TT-LOGID
X-Bc-Bl
X-Trace-Id
X-Auto-Login
X-Dc
X-SRV
Cache-Hits
X-Origin-CC
X-HTML-Minification-Powered-By
X-Varnish-Hits
X-Origin-TTL
Xet-Cookie
X-Varnish-Hostname
X-Loop
X-TNCMS
Mime-Version
X-GEO
Retry-After
X-Cdn
X-Amz-Meta-S3cmd-Attrs
X-Platform-Server
X-Akamai-Transformed
X-S-Maxage
Onion-Location
X-Time
HostName
X-Ratelimit-Remaining
X-Xfnlog-Site
X-Cache-Remote
X-CSRF-Token
X-Cache-Var-Map
X-Tumblr-Pixel-2
X-Cache-Var
X-Tumblr-Pixel-3
X-Proto
X-Cache-Tags
X-Edge-Location
Web-Mar-Node
X-Varnish-Cache-Hits
Webserver
Upgrade-Insecure-Requests
X-Time-Microsecs
X-Tenant
X-Request-Time
X-Endurance-Cache-Level
ServedBy
X-LJ-Flow-ID
X-Xrds-Location
X-VWS-Id
X-EC-Lua
N-Cache
X-ECache
X-AOL-HN
X-AWS-Id
X-GG-Cache-Date
WP-Super-Cache
X-FireWall-Port
CloudFront-Viewer-Country
X-Request-Host
X-B3-SpanId
Nel
X-Correlation-ID
X-Qnm-Cache
From-Origin
X-M-Log
X-M-Reqid
X-Mg-Request-UUID
X-Origin-Response-Time
X-Labrador-Cache-Channel
X-Amzn-RequestId
X-Via-NSCOPI
X-PHP-Host
X-Amz-Apigw-Id
X-NAPM-TraceId
X-Vtex-Remote-Cache
A
X-PBS-Appsvrname
X-Ig-Push-State
BehaviorPad-Version
X-ND-Cache
X-Orig-Expires
X-Hnp-Log
Origin
X-CF-Lambda-Fn
X-Cache-NE
User-Cache-Control
V-Age
Surrogated-Key
Sslversion
X-Cluster
X-Ckpd-Fst-Backend
X-CF-Lambda-Version
X-Cache-Date
X-Block-Status
X-A-Wwc
X-Aed
X-B-Cookie
X-ARC
X-A-Dgt
X-A-Dcw
X-A
X-A-Ccd
X-A-Dam
Rendered-Blocks
Redirect-Candidate
X-Forwarded-Path
Expiry
Fastcgi-X-Cache-Version
X-External-Request-Id
DSUID
DCR-Processing-Time-Ms
CDCHOST
X-Ftr-Request-Id
DCR-Decision-By
L
X-Developer
X-Connection-Hash
X-Conf
Pramga
Odigeo-Trace-Id
X-D
X-Destination
Meta-Geo-Continent
Mobile-Detection-Method
X-Gen-Mode
X-PAYTM-SRV-ID
X-TIM-N
X-S-Cookie
X-V-Cache
X-SD-PageType
X-Processor
X-Slack-Backend
X-S
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Shop-Environment
X-SRCache-Key
X-Rojux
X-Application
X-ScT
X-Vtex-Processado-Em
X-Planisys-CDN-TTL
X-VG-WebCache
X-Planisys-CDN-Rules
X-Session-Fingerprint
X-Planisys-CDN-Cache
Xc-Version
X-Vdms-Path
X-Vdms-Version
X-MP-GENERATED-AT
X-Handled-By
X-RCS-CacheZone
Origin-EX
X-Sucuri-Cache
X-Eu-Site
X-Csrf-Jwt
X-Storefront-Renderer-Rendered
Origin-CC
X-Skip-Cache
X-Core-Mission
X-Envoy-Decorator-Operation
HA-Ipaddr
Host-ID
X-Device-Os
Ha-Gx-Prefs
L5d-Success-Class
X-Epic-Correlation-Id
X-Date
Ssr
Wxu-Next-Commit
Wxu-Next-Hostname
X-Varnish-Beresp-Status
X-Cache-Bucket
X-UnsetCookies
Wxu-Next-Region
X-VarnishDD-TTL
X-VServer
X-Backend-State
X-Accel-Expires-Debug
X-Webstats-RespID
X-Cache-Info
True-Client-Country-4JS
X-CGP
X-Aicache-OS
Release
X-Request-URI
X-Sucuri-ID
State
X-Locale
Traceparent
Vix-Hermes-Req-Id
X-Cdn-Srv
Svr
PFcat
Gh-Request-Id
X-NodeID
X-Hash
X-HN
Arc-Country
X-RateLimit-Remaining-Second
CacheControlHeader
X-Geo-Header
X-Policy
AKAMAI
X-Mvc-Supplant-Cachable
X-RateLimit-Limit-Second
X-Cache-Enabled
X-Li-Pop
X-Li-Fabric
X-Proxy-Upstream
X-Men
X-Location
X-LI-UUID
X-Nyt-Route
X-Rocket-Nginx-Serving-Static
X-Forwarded-Site
X-Old-Content-Length
Cmstype
X-Fastly-Cache
X-Scheme
X-Fetched-On
X-Served-From
X-Server-IP
X-Origin-Time
X-Gdpr
X-Owner
X-Origin-Expires
Cmsid
Fastcgi-Cache-TTL
X-Zone
Environment
Server-Info
Fastly-Drupal-Html
X-NWS-UUID-VERIFY
X-TrackingId
X-Cache-Debug
X-Bip
X-Platform
X-VG-TLSProxy
X-BBC-Edge-Cache-Status
X-Node-Id
X-ATG-Version
X-Viewer-Country
X-Branch-Name
X-HS-Content-Campaign-Id
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Generated-On
X-GeoIP
X-Core-Value
X-Sn-Servicetimems
X-Datadog-Trace-Id
X-Sigma
X-Esi-Check
X-Developers
X-Sigma-Backend
X-Gamma-Serve
X-GeoIP-City
X-Gzip
X-Irp-Debug
X-Req
X-Level-Front-Cache
X-Region-Sid
X-Thinkindot-L3
X-Thanos
X-Fastly-Backend
X-Rocket-Build-Number
X-Request-Start
X-Reqid
X-TH-Server
X-Cdn-Origin
X-Cache-Id
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Locid
X-VC-Cache
TDXMobile
Machine
X-Magnolia-Registration
Req-Svc-Chain
Mail-Subject
Server-Host
Fastly-GeoIP-CountryCode
Thinkindot-Control
Apple-News-Services-Host
X-Adobe-Source
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
We-Hiring
Apple-News-Services-Handled
Fastly-SWR
X-DefElseHash
X-DefHash
Cf-Device-Type
Memcached
NM-Fastcgi-Cache
NGX
X-Is-Gdpr
X-Has-Esi
Adler-Geo
X-NU-AKA-ACS-Version
Is-Eu
X-FC-Vary-Parameters
Fastly-SIE
X-JWT-State
X-Loc
X-DPWN-IS-SECURE
Platform
Web-Mar-Region
X-Response-By
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Amzn-Remapped-Content-Length
X-Cache-Config
X-Origin
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Tx-Id
X-Backend-TTL
X-Pod-Name
X-Worker
X-Qloud-Router
X-Varnish-Remaining-TTL
X-Variation
AMP-Access-Control-Allow-Source-Origin
X-Ua-Device
X-Varnish-Beresp-Ttl
X-Trace-ID
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Mvc-Supplant-OutputCached
X-CLOUD-TRACE-CONTEXT
X-CACHE-KEY
Datacenter
X-CS
X-LB-ID
X-Generated-In
X-Up
Pics-Label
X-API-Version
Magicmarker
X-Datadome
X-NC
S-Rt
CDN
Ms-Author-Via
Candidate-Md5Url
X-Restarts
X-LB-NoCache
Kp-EeAlive
X-DynaTrace-JS-Agent
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Popv
Memory
WWW-Authenticate
X-Via-Popn
NtCoent-Length
WebServer
X-Varnish-Ttl
On-Server
X-TraceId
X-Edge-Pop
Time
X-Vc
X-DC
Env
X-Via-Poph
X-Http-Reason
X-Akamai-Request-ID2
X-Cache-Ttl
X-Tt-Logid
Edge-Cache
X-Wix-Viewer-Type
X-TA-CDN-Provider
X-DW
X-RSL
X-Refresh
X-RPS
X-RPM
X-DB
X-Optimistic-Header
Esi-Enabled
X-DI
X-Action
X-DSS
X-CacheTTL
X-Cache-Backend
X-Srv
GeoIp-Country-Code
X-Minions-Version
X-Service
C-Via
X-Parent-Response-Time
X-Servedbyhost
X-Esi
Accept-Language
X-HA-Backend
X-MSEdge-Flight
Server-ID
X-Cache-PHP
X-Varnish-Beresp-TTL
X-Unique-ID
X-MSEdge-Features
X-Newrelic-Synthetics
X-Cs
X-ZONE
X-TX-ID
X-VCL-Version
X-Urbn-Context-Path
X-Cache-Status-Check
Locale
X-Webkit-CSP-Report-Only
X-Render-Time
X-Urbn-Site-Id
X-Dynatrace
X-Traceid
X-User
X-Fpc
X-App
X-Ec-Fail
X-Ec-GeoHdr
X-LI-Proto
X-URL
X-Webkit-Csp-Report-Only
X-Li-Proto
Test
Proxy-Connection
X-LiteSpeed-Cache-Control
X-FPC
X-B3-Spanid
X-AIR-PT
X-Info
X-Pass-Why
X-NODE
X-Clientip
X-AK-Request-ID
Cdncip
Cdnsip
Geo-Info
Server-Id
Tcn
X-Vcl-Version
X-WADP-Cache
HIT
X-Fmm-Version
My-App
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Request-Id
Cluster
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Clara-WADP
UCS
M-TraceId
Cache-Host
S-Cnection
X-LiteSpeed-Tag
X-HostName
Fastly-Drupal-HTML
Geoip-Latitude
X-CUA
Tracecode
X-Var-Ttl
Resin-Trace
Cf-Int-Pingora-Origin-Digest
X-CSRF-TOKEN
T-Server
X-ID
X-From
X-Ha-Backend
Lfy
GeoIP-Country-Code
Hostname
Fastly-Backend-Name
Ohc-File-Size
Lang
X-Fragments
Hit
User-Agent
X-Pad
X-Mcache
X-Micro-Cache
X-ServedByHost
X-RAMCache
X-Dynatrace-Js-Agent
X-Geo
X-WP-CF-Super-Cache-Cache-Control
X-Backend-Host
X-WP-CF-Super-Cache
X-Via-PopH
X-Via-PopV
X-Via-PopN
Target-Params
X-Edge-POP
X-ElasticPress-Query
ENV
MIME-Version
X-BBC-Origin-Response-Status
X-RateLimit-Reset
X-Release
X-NGINX-Cache
X-Edge-Cache
DataCenter
X-Cdn-Forward
X-Api-Version
X-Check-Cacheable
Load-Balancing
X-APP
X-BCube-Filmed-By
X-VC
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Id
Lb
X-ServerName
X-Ucs
X-HS-Status
EpKe-Alive
Servername
X-Fastly-Backend-Reqs
URI
VNS-Cache
X-Proxy-Cache-Info
VNS-Age
X-Httpd
Path
CPC-Age
X-WA
X-Nc
X-Lb-Nocache
Cache-Key
CPC-Cache
Uri
X-GoCache-CacheStatus
PICS-Label
X-WA-Info
X-UP
Permissions-Policy
FSS-Cache
X-Amz-Meta-Cb-Modifiedtime
X-TRACE-ID
ServerName
WZWS-RAY
Server-Ttl
X-Provided-By
X-ES-SERVER
Producers
Cdn
X-Lb-Id
Cneonction
Cteonnt-Length
Ohc-Cache-HIT
X-Fastly-Cache-Hits
X-B3-ParentSpanId
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Cdn-Request-ID
X-Dw-Trace-Id
X-Apw-Access-Action
X-Vcache
X-Acquia-Purge-Tags
X-Yottaa-OS
X-Acquia-Application-UUID
X-Apw-Access-Object
X-Acquia-Site
X-Akamai-ERPolicy
Shield-Pop
X-Cache-CFC
X-Pool
X-SB
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Apw-Hits
X-Newrelic-App-Data
X-Akamai-ERRuleID
X-Snapshot-Date
X-Apw-Access-Token
X-Acquia-Application-Trace
X-Swift-Error
Pagetype
X-PJAX-URL
Cf-Ipcountry
Vha6-Origin
CF-Cached-On
X-Cms-Context
X-Cache-Ngx
Sid
X-Air-Pt
X-Udemy-Cache-App-Namespace
Req-ID
X-Logging-Id
X-Akamai-Pragma-Client-IP
X-Via-Ucdn
CountryCode
X-CCDN-Origin-Time
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
X-Akamai-Request-ID
GeoIP-Latitude
X-CCDN-CacheTTL
X-UA
X-Http-Count
X-Miniprofiler-Ids
X-Http-Duration-Ms
X-Sentry-ID
X-Te-Duration-Ms
Ngx
X-Hcs-Proxy-Type
X-Varnish-Authentication
X-CacheKey
X-Last-Modified
MD5-Digest
X-Te-Count